var xss = require('xss');
var html = xss('<script>alert("xss");</script>');
console.log(html);
// &lt;script&gt;alert("xss");&lt;/script&gt;

console.log(xss('<SCRIPT SRC=http://xss.rocks/xss.js></SCRIPT>'))
